VYPR
Vendor

Malach It

Products
3
CVEs
6
Across products
8
Status
Private

Products

3

Recent CVEs

6
  • CVE-2026-53431CriJul 30, 2026
    risk 0.52cvss epss 0.00

    Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. Boruta accepts JWT-based client authentication…

  • CVE-2026-53661HigJun 11, 2026
    risk 0.50cvss epss 0.00

    Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the identity “remember me” cookie were set without the Secure attribute. In…

  • CVE-2026-65635HigJul 30, 2026
    risk 0.47cvss epss 0.00

    Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3…

  • CVE-2026-49249HigSep 2, 2026
    risk 0.39cvss epss 0.00

    Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of the user-supplied request body via…

  • CVE-2026-54885MedJul 30, 2026
    risk 0.38cvss epss 0.00

    Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and cloud metadata endpoints. Three code…

  • CVE-2026-55221MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta logged sensitive OAuth and OpenID Connect values in business event logs. Logged values could include…